Maurizio Barbaro
unread,Jun 23, 2016, 6:14:44 PM6/23/16Sign in to reply to author
Sign in to forward
You do not have permission to delete messages in this group
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to security-onion, gilleser...@italtel.com
Hello,
We are using suricata included in security onion 14.04.04 in IDS mode for a while now, and we are facing a problem on packets that are dropped with moderate network traffic (around 150-200 Mbit7s).
In few words we are using suricata to watch mainly two types of packets the SIP one and the UDP one, and observing the server when working, all our SIP packets passed well through IDS to the next server, but more than 70 % of our UDP packets are dropped between the internet network and snort.
our suricata is in IDS mode, with pfring, in VMware environment esxi with input interfaces in passthrough.
Server hosting VMWare ESXi is an HP proliant DL360 gen8, with 16 x 2,5 GHz Intel Xeon E5-2570 cpus. Network interfaces are 1GBit/s running.
Suricata input are eth11 and eth4 that are connected with linux bridge, with eth1 and eth10 respectively.
We will be thankfull to hear from you what is happening. For that we have attached our sostat and netstat -i output .
thank you in advance.
Gilles & Maurizio.